Executive brief
AstrBot, a chatbot framework, contains a security flaw in how it manages scheduled tasks. In shared group chats, one user can view, modify, or delete tasks created by other users in that same group. Most significantly, if an attacker modifies a task created by an administrator, the bot may execute the attacker's instructions with administrative privileges when the task runs.
Technical details
An improper authorization vulnerability exists in AstrBot's `FutureTaskTool.call` function within `astrbot/core/tools/cron_tools.py`. The application scopes task management (list, edit, delete) to the Unified Message Origin (UMO/session) rather than the individual task owner. A remote attacker sharing a group session can modify the `payload["note"]` of another user's task. Because the edit operation preserves the original creator's `sender_id`, the scheduler later derives the `cron_event.role` from the original owner. If the victim is an administrator, the attacker's modified task content will execute with 'admin' privileges. Public exploits have been released, and the vendor has not yet provided a patch.
Affected products
- AstrBotDevs AstrBot <= 4.25.2
Timeline
- 2026-06-01: disclosed: Initial researcher gist published
- 2026-07-12: advisory: NVD/VulDB advisory published